Domain: saintaardvarkthecarpeted.com
Stories and comments across the archive that link to saintaardvarkthecarpeted.com.
Stories · 43
-
Canadian Bureacracy Can't Answer Simple Question: What's This Study With NASA?
Saint Aardvark writes "It seemed like a pretty simple question about a pretty cool topic: an Ottawa newspaper wanted to ask Canada's National Research Council about a joint study with NASA on tracking falling snow in Canada. Conventional radar can see where it's falling, but not the amount — so NASA, in collaboration with the NRC, Environment Canada and a few universities, arranged flights through falling snow to analyse readings with different instruments. But when they contacted the NRC to get the Canadian angle, "it took a small army of staffers— 11 of them by our count — to decide how to answer, and dozens of emails back and forth to circulate the Citizen's request, discuss its motivation, develop their response, and "massage" its text." No interview was given: "I am not convinced we need an interview. A few lines are fine. Please let me see them first," says one civil servant in the NRC emails obtained by the newspaper under the Access to Information act. By the time the NRC finally sorted out a boring, technical response, the newspaper had already called up a NASA scientist and got all the info they asked for; it took about 15 minutes." -
Samsung Plants Keyloggers On Laptops
Saint Aardvark writes "Mohammed Hassan writes in Network World that he found a keylogger program installed on his brand-new laptop — not once, but twice. After initial denials, Samsung has admitted they did this, saying it was to 'monitor the performance of the machine and to find out how it is being used.' As Hassan says, 'In other words, Samsung wanted to gather usage data without obtaining consent from laptop owners.' Three PR officers from Samsung have so far refused comment." -
FSF Settles Suit Against Cisco
Saint Aardvark writes "The Free Software Foundation has announced that they've settled their lawsuit with Cisco (reported earlier here). In the announcement, they say that Cisco has agreed to appoint a Free Software Director for Linksys, who will report periodically to the FSF; to notify Linksys customers of their rights; and to make a monetary donation to the FSF. An accompanying blog entry explains further: 'Whenever we talk about the work we do to handle violations, we say over and over again that getting compliance with the licenses is always our top priority. The reason this is so important is not only because it provides a goal for us to reach, but also because it gives us a clear guide to choosing our tactics. This is the first time we've had to go to court over a license violation.'" -
Letter Casts Doubt On Yahoo China Testimony
Saint Aardvark writes "A hand-written letter has surfaced that sheds new light on the case of Chinese reporter Shi Tao. The letter (PDF), believed to be from Chinese police, 'is essentially a standardized search warrant making clear that Chinese law enforcement agencies have the legal authority to collect evidence in criminal cases. This contradicts Yahoo's testimony (PDF) to Congress in 2006 that they 'had no information about the nature of the investigation.' 'One does not have to be an expert in Chinese law to know that 'state secrets' charges have often been used to punish political dissent in China,' says Joshua Rosenzweig, manager of research and publications for The Dui Hua Foundation. Shi Tao was sentenced to 10 years in prison for his reporting on the Tianamen Square massacre." -
Cell Phone CEOs Marked For Phone Cloning
Saint Aardvark writes "When Sarah Drummond got back from Israel, she found a cell phone bill for more than $12,000. She contacted her cell phone provider to let them know that someone had stolen her phone, but they weren't interested in helping her and told her she'd have to pay. In preparing for small claims court, she and her partner found out that not only does her company have the ability to spot unusual activity on a cell phone account, the company executives' own phones have been targeted by a group linked to Hezbollah. From the article: 'They were using actually a pretty brilliant psychology. Nobody wants to cut off [CEO] Ted Rogers' phone or any people that are directly under Ted Rogers, so they took their scanners to our building, like our north building, where our senior top, top, top executives are. They took their scanners there and also to Yorkville, where there are a lot of high rollers and like it would be a major PR blunder to shoot first and ask questions later. . . . Nobody wants to shut off Ted. Even if he is calling Iran, Syria, Lebanon, and Kuwait.'" -
FreeBSD Logo Contest Winner Announced
Saint Aardvark writes "Earlier this year, the FreeBSD people announced a competition to design a new logo. Welp, the winner has been announced, and you can check out the new logo. Congratulations to Anton K. Gural on the spiffy work!" -
Reducing Plant Stress Leads to Martian Farms
Saint Aardvark the Carpeted writes "NASA is looking for ways to get plants to grow on Mars -- and surprisingly, reducing their stress is a good first step. By splicing genes from Earth-bound extremophiles into seeds whose descendants are destined for the red planet, scientists hope to breed plants that can handle the wide range of temperatures (pdf) that will be found on Mars." -
Net Marketers Worried as Cookies Lose Effectiveness
Saint Aardvark writes "The Globe and Mail reports that Internet marketers are worried about the decreasing persistence of cookies. Almost 40% of surfers delete them on a monthly basis, says Jupiter Research -- a fact one marketers attributes to incorrect associations with spyware and privacy invasion. United Virtualities' Flash-based tracking system is mentioned as a possible substitute...though they don't mention the Firefox plugin that removes them, or talk in any meaningful way about why people might want cookies gone. Still, the article is a good overview of life from the marketer's perspective." -
Current Crypto Trends with Bruce Schneier
Saint Aardvark writes "SecurityFocus has published an interview with Bruce Schneier. Fascinating stuff, especially the level-headed assessments of the NSA, spam and the impact of full disclosure: 'Q: Since most crypto protocols on the internet, such as SSL or SSH, uses public-keys to build a secure channel, wouldn't a unexpected public disclosure create a chaos on the internet ? A: No. Chaos is hard to create, even on the Internet. Here's an example. Go to Amazon.com. Buy a book without using SSL. Watch the total lack of chaos.'" -
US Air Force Building Space Router
Saint Aardvark writes "From the ISTS daily news comes a story on the US Air Force seeking to build a space router. From TFA: "Northrop Grumman and Caspian Networks are collaborating to develop an Internet Protocol router that can withstand the constant barrage of solar radiation in orbit. The space-hardened IP router will be part of the Air Force's Transformational Satellite Communications System, which will provide IP-based communications to warfighters." I wonder what the ping times would be like..." -
Spammers' Upend DNS
Saint Aardvark writes "eWeek reports on the latest trick of spammers: getting around DNS-based lookups. By registering a domain *after* the spam goes out advertising it, they can get around blacklists. However, that causes all sorts of problems for ISPs and anti-spam services. Paul Judge, CTO at Ciphertrust, says "Even in large enterprises, it's becoming very common to see a large spam load cripple the DNS infrastructure."" -
Wilco on P2P, Digital Music and the Internet
Saint Aardvark writes "As if Wilco wasn't the coolest band in existence anyway, Wired has an interview with them about their relationship with P2P, the Internet, and their fans. For example, they were contacted by fans who'd downloaded A Ghost Is Born before it was released. Lead singer Jeff Tweedy explains, 'They wanted to send money to express solidarity with the fact that we'd embraced the downloading community. We couldn't take the money ourselves, so they asked if we could pick a charity instead -- we pointed them to Doctors Without Borders, and they ended up receiving about $15,000.' Many other choice quotes make this a fascinating read." -
Thinking About the SnitchCam
Saint Aardvark writes "From Dan's Data comes a fascinating look at the consequences of tiny, wireless video cameras: "Right now, it's hard to prove that (for instance) riot police really beat the crap out of innocent people at a demonstration....Live streaming video from multiple cameras operated by lots of people at the same time, though, will be a different matter. Even without cryptographic jiggery-pokery, it'll be practically impossible to get away with even minor editing-room spin doctoring, if thousands of people around the world have the original footage on their hard drives." " -
NASA Quakesim Predicts 15 Out of 16 CA Quakes
Saint Aardvark writes "NASA's QuakeSim project has successfully predicted15 out of 16 of California's earthquakes with magnitude > 5, including 11 since the map was published in 2002. "So far, the technique has only missed one earthquake, a magnitude of 5.2, on June 15, 2004, under the ocean near San Clemente Island."" -
Lexar JumpDrive Password Scheme Cracked
Saint Aardvark writes "Lexar describes the JumpDrive Secure as "loaded with software that lets you password-protect your data. If lost or stolen, you can rest assured that what you've saved there remains there with 256-bit AES encryption." @stake has a different take: The password can be observed in memory or read directly from the device, without evidence of tampering." And best of all, the punch line: "[The password] is stored in an XOR encrypted form and can be read directly from the device without any authentication." That's why I use ROT-13 for my encryption needs." -
20,000 Zombie PCs -- $3000
Saint Aardvark writes "From F-Secure blog comes these links to two USA Today articles on spamming. The first gives an example of how a grandmother ended up becoming a security expert after Comcast cut her connection for spamming. The second quotes spammers advertising networks of Zombie PCs for sale. The price? $3000 for 20,000 machines." -
IE Download.Ject Exploit Fixed
Saint Aardvark writes "Just in time for the weekend, the Internet Storm Center is reporting that Microsoft is providing a fix for the Download.Ject vulnerability that hit IE late last month. The press statement says that it'll hit Windows Update later today..." -
Examining an Automated Spam Tool
Saint Aardvark writes "SecurityFocus has published an excellent column detailing how spammers r00ted an Apache server, and used it to send spam. The tool they used is (I hate to admit it) pretty sophisticated: it has macro capabilities, picks up email addresses from and reports success or failure to the master server. It's a very frightening read...and so is this: Message Labs reports that they now intercept 27 spam emails per second, up from 2 per second this time last year. Virus-created proxies are mainly to blame." -
Microsoft Forgets To Renew Hotmail.co.uk
Saint Aardvark writes "The Register is reporting that Microsoft forgot to renew their hotmail.co.uk domain. A Good Samaritan renewed it for them, but was unable to get a response from anyone at Microsoft. Those who forget history are doomed to repeat it." -
Tampa Police Give Up On Face Recognition Cameras
Saint Aardvark writes "The city of Tampa has given up on their face-recognition system attached to street surveillance cameras." -
Windows Vulnerabilities Revealed, Patched
Saint Aardvark writes "A big MS Windows remote vulnerability has just hit BugTraq. It concerns a buffer overflow in MS' DCOM, and affects Win2k through Server 2003; here's the security advisory from Microsoft. This is in addition to an earlier vulnerability concerning conversion from HTML to RTF - there's a separate security advisory from Microsoft for this one, and it affects Win98 and NT 4.0 through Server 2003. Patch early, patch often." There's also a CNET News story with a little more explanation on the newest vulnerability. -
Scientists Say Cosmic Rays May Cause Global Warming
Saint Aardvark writes "Researchers in Israel and Germany suggest that variations in cosmic radiation as the sun orbits the galactic core may be responsible for changes in the Earth's climate -- including more than half of the change in the 20th century. A PDF of their article is available from GSA Today or read the abstract for their Physical Review Letters article." -
WLANs As Spam Conduit
Saint Aardvark writes "According to this article, a honeypot was recently set up on two wireless LANs. 25% of the connections observed were deliberate, and 71% of those were to send spam. Even more reason to take care of your ether." These statistics should be taken with a salt lick... -
Security Hole Found in 4.3.0
Saint Aardvark writes "The good folks at PHP.net have warned of a serious vulnerability in PHP 4.3.0: 'Anyone with access to websites hosted on a web server which employs the CGI module may exploit this vulnerability to gain access to any file readable by the user under which the webserver runs. A remote attacker could also trick PHP into executing arbitrary PHP code if attacker is able to inject the code into files accessible by the CGI. This could be for example the web server access-logs.' It's recommend that you upgrade to 4.3.1 right away." -
Spam Archive opening FTP service December 4
Saint Aardvark writes "The FTP archives for spamarchive.org will be opening on December 4, according to this Wired article. But there already appear to be some archives available." I tried saving my spam for awhile just for giggles, but seeing that file grow to 100+ megs made me so angry I had to delete it. Currently getting ~200 spam every day, and now often they attach images so they are 100k+. Yay Internet! -
ISP Sued Over Suspended Email Account
Saint Aardvark writes "A Canadian woman is suing her former ISP over their suspension of her email account. Their accounting system screwed up, and they suspended her account while they sought payment from her. What she didn't realize was that email sent to that address continued to pile up, without any notification to the sender that she had no access to it. She lost a chance at a $65,000 contract job at the Discovery channel because of this. Read the article at CNet, the complaint she brought to the Canadian Privacy Commisioner, and further details from the woman herself on Cryptome.org." -
Graphing Randomness in TCP Initial Sequence Numbers
Saint Aardvark writes "This is neat: Graphic visualization of how random TCP Initial Sequence Numbers really are for different OSs. It's a great way of seeing how secure a TCP stack really is. Cisco IOS is great; OS9, OpenVMS and IRIX aren't. Posted to the ever-lovin' BugTraq mailing list." This is a follow-up to the previous report. -
Randomizing Survey Answers For Accuracy
Saint Aardvark writes: "The New York Times reports that two researchers at IBM have come up with a way to persuade people to give correct answers to survey questions: randomize the results. Strangely enough, they can get accurate information out of the aggregate of enough answers -- but it's completely anonymized. Since conservative estimates say nearly half of all survey answers are bogus, there's an interest in persuading people to be more truthful. As ever, you can use the Random NY Times Registration Generator to falsify your registration details and read the article..." -
Got Evil? Buy it Here!
Saint Aardvark writes "I just came across VillainSupply.com, and I'm sold. From Doomsday Devices to Robotic Tigers to Randroids, these guys have got it all. Don't forget the convenient, accessible self-destruct device!" -
Don't Hit That Back Button
Saint Aardvark writes: "From the Bugtraq mailing list comes this warning: 'Using the Back Button in IE is dangerous'. When hitting the back button, javascript links will be executed in the security zone of the last url viewed. Proof-of-concept included in the warning will execute minesweeper or read your Google cookies." -
Fighting Spam on the Home Front
Saint Aardvark writes: "Something interesting from the SecurityFocus Honeypot mailing list: a couple of honeypots for spammers. This message has a link to a how-to page for setting up a Sendmail honeypot to trap spammers, and the status page for a honeypot in Moscow that's trapped spam meant for >1.7 million recipients. The author mentions using a honeypot in conjunction with the Distributed Checksum Clearinghouse -- this seems like a great way identify both spammers and their messages."And C-Moan writes: "Wireless spam volume is likely to increase in the coming years. But smart use of spam-fighting measures can go a long way toward eliminating the problem. This article provides info about the latest crop of e-mail filters and enhanced mail client options, as well as two roll-your-own programming platforms that could help keep your in-boxes spam free."
-
2.5.4 Kernel Out
Saint Aardvark writes: "Just in time for my 30th birthday, the new kernel is out...how did he know? Thanks, Linus! Change log here. I usually stick to stable stuff, but I think I'll try this for fun." Reader Scooby Snacks writes: "Be sure to use the patches and pick from the fine list of mirrors." -
Security Hole in Morpheus
Saint Aardvark writes: "The BBC reports that they've been contacted by a group claiming to be able to copy any file off some Morpheus user's hard drives. Apparently a bug allows for a great deal more file-sharing for some users of the software than intended ..." Man this thing got submitted a lot. I've never actually seen Morpheus, but apparently a lot of readers have! There really isn't a lot of information except that if you're running Morpheus, you might as well consider your hard drive world readable ;) -
802.11b Space Suits
Saint Aardvark writes "The BBC has an article here about WearSat, the new generation of space suits: embedded RISC processor, 802.11b networking, VGA heads-up display, and 1GB microdrive. I want one for my rec room." -
Who Invented Packet-Switching?
Saint Aardvark writes "It's how the Internet works, and now who invented packet-switching is under dispute. A posthumous paper by British scientist Dr. Donald Davies disputes the claim by Leonard Kleinrock to have invented the technique, saying Kleinrock never took it beyond the case of a single node. Kleinrock, whose lab was the first node on Arpanet, is willing to concede that Davies invented the term "packet-switching."" -
Slashback: Snapshots, Amends, Bazaarity
Slashback brings you some follow-ups tonight about Gartner's recommendation to dump IIS, Charles Connell vs. Eric S. Raymond on Open Source project management, xStore and the GPL, and (yes) the results of Deep Space 1's latest Final Mission.Microsoft is just as secure as the competition, says Microsoft. Jon_E writes: "According to this article Microsoft is responding to the Gartner Report which recommends that enterprises drop IIS by claiming unfair targeting due to their popularity."
Whether because of better-trained or more vigilant administrators, or some other factors, the Apache servers running many web sites certainly haven't seen the devastating outages in the past month (Code Red, Nimda) as certain large IIS installations have.
If animated, this might make a really good Saturday cartoon. cconnell writes "Last September, slashdot published my critique of Eric Raymond's essay The Cathedral and the Bazaar. There was a lively (and sometimes scorching) discussion that followed. Here is Eric's reply to my critique, which Slashdot readers might enjoy. And here is my reply to Eric."
This was not faked in the same studio as the "lunar landings." mrsmalkav writes "Deep Space 1 has passed by Comet Borrelly within 1400 miles and took some very pretty pictures of the comet's core, all while collecting lots of data about said comet. NASA's press release discusses some of the details and findings of the flyby.
This is actually really impressive given that there was very little hope for this mission. From the Mission Logs on DS1's site, '[T]o be honest, DS1's visit with the comet simply is unlikely to work as well as we hope. Many mission logs have described the difficulty of keeping this aged and wounded bird aloft, and the encounter with Borrelly will present Deep Space 1 with the greatest challenge yet in its historic trek through the solar system.'"
Saint Aardvark writes "Space.com has an article about the images taken by DS-1, and they're stunning." And eldurbarn points to the NASA Images of comet Borrelly online at JPL.
How to satisfy customers with license objections, Part II brtb writes: "Soon after Slashdot posted my DiscZerver-GPL writeup last week, xStore added a link in their Download section for information about the use of GPL software in their products. Below is the e-mail I received in response (address changed to protect the spamless). Congratulations to xStore for supporting Free Software and bringing the DiscZervers into compliance with the GPL.
From: "Support" [support@xstoreonline.com]
To: "brtb" [slashdot@brtb.org]
Subject: "RE: GPL SOURCE CODE"xStore is committed to complying to the full letter and spirit of the GPL. We are currently investigating the allegations of non-GPL compliance and communicating with the GNU.ORG and Free Software Foundation on this issue. We will produce a response to your request that is mutually acceptable to the copyright holders of the programs we have used that fall under the GPL and xStore itself. Due to the recent acquisition of this product, we are still in the process of preparing the required source code for distribution. xStore is commited to bring the DiscZerver product into GPL compliance, if it is indeed found to be not in compliance.
In the meantime, please provide xStore with information so that we can send you, the user of this product, the package that you are entitled to. Please provide the serial number of your DiscZerver product and the 'system page' with your response. The 'system page' is located at [http://your_Zerver_name_or_IP_address/admin-cgi/s ystem]. In addition, please send us a self addressed stamped envelope suitable for mailing a CD-ROM along with $14.95 to:
xStore, Inc.
Federal Highway Center
1200 North Federal Highway
Suite 200
Boca Raton, FL 33432After we receive your written request along with the above items, we will process it and promptly send you the disc when it becomes available.
This thanks to the mostly behind-the-scenes work of people at the FSF. Congratulations to xStore for respecting the intent of the programmers whose work they're consolidating and packaging.
-
Deep Space 1 Completes Comet Fly-by
Saint Aardvark writes: "All right...Space.com is reporting here that NASA's Deep Space 1 probe successfully made it through Comet Borrelly -- pretty good for a spacecraft using up the last of its fuel, 'way past its expected lifetime, doing something it wasn't designed to do'. About 30 pix are being downloaded right now, and there's a press conference planned for Tuesday. In the meantime, read NASA's press release here. Way to go, DS-1 and NASA!" -
Beer In Space
Saint Aardvark writes: "Check it out...NASA recently sent up an experiment to see how well beer could be brewed in space. The result? One millilitre of space brew. Can orbital microbrew be far behind?" They've been making great strides since our first Beer in Space article. -
Eliza for Spam
Saint Aardvark the Carpeted writes "Check this out for sheer genius...This guy has posted to Perl Monks a script that uses the Perl Eliza module to respond to spam. Check it and contribute your suggestions for improved vocabulary." The downside of course is that spammers never set their reply correctly (which I think is forgery, and should be treated as such) so this is probably more academic then useful, but its definitely funny. -
How to Burn a Magnesium NeXT Cube
Saint Aardvark the Carpeted writes "How do you set a magnesium NeXT cube case on fire? It took this guy two years, *two* cases and the cooperation of Lawrence Livermore Lab's burn cell." A seriously bizarre tale, but worth a read if you're curious. And I have one of those cubes in my office... all sorts of fiendish ideas start. -
Physicist says Defense Dept. Trying to Silence Him
Saint Aardvark the Carpeted writes "The New York Times reports here that Dr. Theodore Postel, a physicist at MIT, is accusing the US Department of Defense of trying to censor his criticism of the missile defense plan. Postel analysed a DOD report saying that, contrary to Postel's previous criticism, their prototype antimissile system could not distinguish between decoy and real warheads; he determined that the data had been distorted by TRW, the contractor responsible for the prototype. After the report was released, the DOD realised that it contained classified data, but by then it had already been distributed on the 'net(links, please!). Now they're telling MIT to confiscate the document from Postel and stop him from disseminating it, or lose the $320 million/yr contract to run the Lincoln Laboratory." -
Australians to Build Spaceport on Christmas Island
Saint Aardvark the Carpeted writes: "CNN reports here that they're jumping into the satellite launching business by building a spaceport on Christmas Island. At only 10 degrees from the equator, the location offers cheaper launches for the launch vehicles, which the government has already agreed to buy from Russia in May." -
Continents on Titan?
Saint Aardvark writes: "CNN reports here that a second bright spot has been found on Titan. The speculation is that it's a continent, but scientists can't be sure until Cassini arrives at Saturn and drops the Huygens probe through the atmosphere."